Saturday, August 1, 2026

News

AI May Have Helped Attackers Steal $38 Million in Bitcoin From Coldcard Wallets

MarketPatryk Raba

Nearly 500 Coldcard hardware wallets were drained of 594 BTC, worth about $38 million, in just 25 minutes. Maker Coinkite suspects attackers used AI to uncover a five-year-old flaw in its key-generation code.

Contents
  1. What went wrong in Coldcard
  2. The role of artificial intelligence
  3. Scale of the losses and industry response
  4. What it means for crypto users

On Friday, July 31, between 1:31 and 1:56 UTC, someone drained roughly 500 Coldcard hardware wallets in just 25 minutes, making off with a combined 594 bitcoin worth close to $38 million at the time. Coinkite, the device maker, has admitted the attack exploited a key-generation flaw that had been sitting in its software for five years, and it isn't ruling out that hackers found it with the help of artificial intelligence.

What went wrong in Coldcard

Bitcoin security teams at Block found that Coldcard's code contained two random number generator implementations. Starting in March 2021, with firmware version 4.0.0, the devices began skipping the hardware randomness generator and falling back to predictable, software-based key generation fed by non-secret chip data such as the serial number and clock value.

In practice, that meant the effective randomness of seed phrases dropped from an intended 128 bits to around 40 bits on the Mk3 model and around 72 bits on the Mk4, Mk5 and Q. A key that weak could be brute-forced in a reasonable amount of time, especially with the computing power commercially available today.

The role of artificial intelligence

Coinkite has no proof that the attackers actually used AI to find the flaw, but considers it the most likely scenario. Coldcard's code is open source, and independent researchers have already shown, after the incident became public, that AI models can locate this specific bug relatively quickly by searching the public repository.

AI-assisted code review can now find hidden bugs faster than even the industry's most experienced experts - Rodolfo Novak, CEO of Coinkite
If your firmware is open source, or has ever been public, assume it is already being read by both attackers and defenders alike - Rodolfo Novak, CEO of Coinkite

Paradoxically, Coinkite itself had previously run a similar code analysis using an advanced AI model and failed to detect the vulnerability, which shows how uneven the effectiveness of such reviews can be. Some security specialists are pushing back on the AI-focused narrative, pointing out that conventional code review, testing, or a seed-generation audit could have caught this bug years earlier without any artificial intelligence involved.

Scale of the losses and industry response

The stolen funds, 562 of the 594 BTC, ultimately ended up at a single address that remained untouched at the time of reporting, making the funds harder to trace further. Coinkite has released emergency firmware updates, but warns that installing the patch alone does not fix the problem for keys already generated. Owners of affected models need to create an entirely new seed and move funds from their old wallets onto it.

Estimates of total risk exposure run well above the amount actually stolen: some analyses put it at as much as 1,128.47 BTC, worth about $71.1 million, potentially at risk across the Mk3, Mk4, Mk5 and Q models. Rival manufacturer Trezor was quick to state that its devices are not affected by this particular flaw and that customer funds remain safe.

What it means for crypto users

The Coldcard case lands at a moment when trust in hardware wallets rests precisely on the assumption that offline key generation is safer than keeping funds on an exchange. A five-year-old flaw shows that even audited, open-source code can hide a bug undetected for years, and the growing availability of AI code-analysis tools is changing the real-world timeline in which such a vulnerability can be found and exploited by an attacker.

For Coldcard wallet owners, the priority now is checking their firmware version and generating a new seed according to the manufacturer's instructions, not simply installing the patch. For the rest of the market, it's another sign that AI models are already shortening the gap between when open-source code is published and when a critical bug in it gets found, regardless of whether the perpetrators in this specific case actually used one.

Share: